This page is written for the people who have to sign off the decision: the security officer, the data protection officer, and whoever owns the archive. It sets out plainly what happens to your material, where it is held, who can reach it, and what we do not do with it.
Download this summary as a two-page PDF — for circulation, security review or a board paper.
The common arrangement in this market is a shared platform with a logical partition between customers. That is not what RUNA is. Your organisation receives its own installation: its own virtual machine, its own document store, its own index, its own models running for you.
Your documents are not combined with any other customer's material, and no other customer's questions can reach into your archive.
Your documents and the questions asked of them are not passed to an AI provider, an analytics service, or any other external party.
RUNA uses open-weight language models that we operate ourselves, alongside your archive. There is no external model call behind an answer.
A virtual machine of your own, on hardware RUNA operates and controls — not a tenancy inside a shared application. Dedicated physical hardware is available where a customer's requirements call for it, on separate commercial terms.
We do not disclose who our customers are. A customer is named publicly only where they have agreed to it.
Your installation runs on hardware RUNA operates in a high-security data centre in Switzerland, built into a mountain. It is not a region of somebody else's cloud with a Swiss label attached — it is equipment we control, in a place with a physical address, a perimeter and a door.
That matters for two separate reasons, and they are worth keeping apart. Physically, the facility is built for material that must not be lost or reached. Legally, RUNA is a Swiss company operating under Swiss federal data protection law, which means your legal colleagues have no third-country transfer to assess and no transfer impact assessment to write.
Two questions sit behind this heading, and both deserve a straight answer: who inside your organisation can see what, and what access RUNA itself has. We would rather set that out here than have you discover it in a security review.
Who may use the installation, and what parts of the archive they may question, is configured with you at deployment and remains under your control afterwards.
We operate the installation, so a small number of named RUNA engineers hold administrative access for deployment, maintenance and support. That access is controlled, logged, and defined in the data processing agreement. Nobody at RUNA reads your documents in the course of ordinary operation.
Where investigating a problem would require sight of your material, we ask first. It is your archive, and access to it for support purposes is your decision to give.
Every output of the system is a draft for expert review. RUNA does not decide anything: a named person in your organisation approves the work, and the system supplies the traceability that makes that review quick.
Questions asked, the sources used to answer them and the answers returned are recorded in your installation, so that use of the system can be evidenced to an auditor.
You choose which parts of your archive are loaded. Nothing is collected from your systems on its own initiative, and nothing is added without you.
Text, tables, scanned pages and the content of graphics are extracted and indexed within your own environment. No part of that processing happens outside it.
Your material is never used to train or improve a model. It does not contribute to answers given to anyone outside your organisation, and it is not analysed for any purpose of ours.
Documents can be added, replaced when a newer approved version exists, and superseded material can be retired so that it stops influencing answers.
When you delete a document it is removed from the live system and from the index immediately, and it can no longer appear in any answer. Encrypted backups are held for disaster recovery, and a copy may remain in a backup until that backup is overwritten in the normal cycle. The retention period is stated in your contract.
If you leave us, your installation and its contents are deleted on the same terms, and we will confirm it in writing.
A data processing agreement under Swiss law forms part of the standard contract, setting out the purposes of processing, the controls, the sub-processors and the deletion terms.
Swiss law governs, and we accept the equivalent obligations under the European regime as well — most of our customers must comply with it, and a supplier who does not simply moves the problem to them.
Send us your security assessment and we will complete it properly rather than returning a brochure. Where the answer is "not yet", it will say so.
RUNA does not hold ISO 27001 certification today. We say so rather than implying otherwise, and we are happy to discuss what we do instead, and when that changes.
If you are assessing RUNA for your organisation, send us your security questionnaire and we will complete it in writing. If it is easier to talk first, we will arrange an hour with the people who built the system rather than with a sales engineer reading from a script.
Want to know moreOr read how it works.